weex-login[.]at
“Weex Login Portal | Access Your Trading Account”
weex-login.at — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Across; घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 1/93 (SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 56/100. रजिस्ट्रार: Iqweb.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of the domain weex-login.at confirms its classification as a credential phishing site targeting users of trading platforms. The domain was registered on February 27, 2026, through registrar Iqweb, and resolved to IP 186.2.175.29, hosted on AS59692 (IQWeb FZ-LLC) in Belize. The page title, 'Weex Login Portal | Access Your Trading Account,' explicitly indicates an attempt to harvest login credentials for trading services. The site was detected on one security blocklist and flagged by one of 93 security vendors on VirusTotal, though the limited detection count does not diminish the confirmed phishing activity.
Technical indicators reveal the use of Node.js, Vue.js, Nuxt.js, jQuery, and Hammer.js, alongside DDoS-Guard for protection, suggesting a moderately sophisticated infrastructure. Nameservers include pns71.cloudns.net, pns72.cloudns.com, pns73.cloudns.net, and pns74.cloudns.uk, which are not inherently malicious but are consistent with domains used for short-lived phishing campaigns. The SSL certificate was issued by Let's Encrypt (R13), a common choice for both legitimate and malicious sites. Gridinsoft assigned a trust score of 0/100, and the domain was blocked by PhishDestroy, further corroborating its malicious status.
As of July 24, 2026, the domain is offline, though defenders should treat any reactivation as a high-risk event. Organizations are advised to block the domain and its associated IP at the perimeter, monitor for credential reuse attempts from affected users, and review logs for connections to 186.2.175.29 or related CloudNS nameservers. The exact phishing kit or additional infrastructure (e.g., C2 servers, redirect chains) remains unconfirmed, but the combination of technical indicators and detection by security vendors justifies immediate defensive action.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of weex-login.at · checked Mar 2, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260227-47B687 Recipient: abuse@iqweb.io क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।